US2016321657A1PendingUtilityA1

Digital signature authentication

Assignee: FIRST DATA CORPPriority: Feb 5, 2007Filed: Jul 7, 2016Published: Nov 3, 2016
Est. expiryFeb 5, 2027(~0.5 yrs left)· nominal 20-yr term from priority
G07F 7/1075G06F 17/30887G07F 7/122G06Q 20/355G06Q 20/4014G06Q 20/4012G06Q 20/3829G06Q 20/409G07F 7/1091G06Q 20/3825G06Q 20/401G07F 7/08G07F 7/1025G06Q 20/40145G06Q 20/10G06Q 20/341G07F 7/1008G06Q 20/40G06F 16/9566
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A systems and methods for authenticating a consumer with a transaction card using digital signatures according to one embodiment of the invention is disclosed. These systems and methods allow consumers to digitally sign transaction information with a private key. The private key may be used to digitally sign the transaction, for example, through a hosted or local system that protects the integrity of the private key. A financial institution may authenticate the consumer by decrypting the digital signature with a public key.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for authenticating an electronic transaction between a consumer and a merchant, wherein the method occurs at a consumer's computer and comprises:
 enrolling a debit card for digital signature authentication at a financial institution;   initiating a transaction between the consumer and the merchant over the Internet;   selecting a payment scheme that includes payment using the debit card;   receiving a request for a digital signature from the merchant, wherein the request includes transaction information;   receiving an authentication scheme from the merchant;   accessing the authentication scheme;   gaining access to a private key as determined by the authentication scheme;   creating a digital signature by encrypting the transaction information with the private key; and   sending the digital signature to the merchant.   
     
     
         2 . The method according to  claim 1 , wherein the financial institution is selected from the group consisting of an issuer authentication server (IAS) and a cardholder account directory service (CADS). 
     
     
         3 . The method according to  claim 1 , wherein the authentication scheme is a URL that points to a plug-in residing on the consumer's computer system, wherein the plug-in provides access to the private key. 
     
     
         4 . The method according to  claim 3 , wherein the plug-in is operable to open local software on the consumer's computer that performs encryption using the private key. 
     
     
         5 . The method according to  claim 3 , wherein the plug-in is operable to interact with a device selected from the group consisting of a biometric scanner and a smartcard reader. 
     
     
         6 . The method according to  claim 1 , wherein the authentication scheme is a URL pointing to a webpage hosted by the IAS, wherein the webpage provides access to the private key. 
     
     
         7 . The method according to  claim 1 , wherein encrypting transaction information comprises encrypting the transaction information using an encryption scheme selected from the group consisting of RSA encryption, the digital signature algorithm, Schnorr signature, Pointcheval-Stern signature algorithm, the Rabin signature algorithm, any of the SHA algorithms, the undeniable signature algorithm, ECDSA, DSA, the ECC algorithm, elliptical curve techniques, Paillier cryptosystem, the EIGamal algorithm, and the Diffie-Hellman key exchange. 
     
     
         8 . The method according to  claim 1 , wherein the consumer gains access to a private key through the authentication scheme. 
     
     
         9 . The method according to  claim 1 , wherein the authentication scheme includes requiring the consumer to enter information selected from the group consisting of an answer to a question, a biometric sample, and a PC scan. 
     
     
         10 . The method according to  claim 1 , wherein the transaction information comprises information selected from the group consisting of transaction currency code, transaction amount, transaction ID, transaction reference number, transaction time, transaction ship data, account number, consumer name, and merchant name. 
     
     
         11 . The method according to  claim 1 , wherein:
 initiating a transaction between the consumer and the merchant over the Internet comprises sending information associated with an account corresponding to the debit card and the account information does not include a passcode or a personal identification number (PIN) for the account;   the authentication scheme comprises a hosted or a local digital signature service; and   the digital signature does not include a passcode or personal identification number (PIN) for the account.   
     
     
         12 . The method according to  claim 11 , further comprising receiving a receipt URL from the financial institution. 
     
     
         13 . The method according to  claim 11 , wherein the received account information includes a primary account number (PAN) of the debit card. 
     
     
         14 . The method according to  claim 4 , wherein the URL sent to the consumer's computer as part of the authentication scheme is configured to automatically direct the consumer's web browser to the URL where the plug-in may be launched. 
     
     
         15 . The method according to  claim 14 , wherein the plug-in is configured to interface with a smartcard reader or biometric detector. 
     
     
         16 . A system for authenticating an electronic transaction between a consumer and a merchant, wherein the system comprises:
 a merchant system connected to the Internet and accessible by a consumer;   a merchant processor adapted to process transactions for the merchant, wherein the merchant processor is in communication with the merchant;   an issuing authentication server (IAS) adapted to host an Internet based authentication scheme for the consumer with enrolled debit cards;   a cardholder account directory service (CADS), wherein the CADS is adapted to provide enrollment information regarding debit cards; and   a financial network, wherein the financial network is adapted to provide communication between the merchant processor, the IAS and the CADS;   wherein:
 the merchant receives a request from a consumer to use a debit card for a transaction between the consumer and the merchant; 
 the merchant requests enrollment information for the debit card used by the consumer from the CADS through the merchant processor; 
 if the debit card is enrolled, the CADS requests from the IAS a URL pointing to an Internet based authentication scheme for the debit card; and 
 the URL pointing to an Internet based authentication scheme is sent to the consumer for authentication of the debit card for the transaction. 
   
     
     
         17 . The system according to  claim 16 , wherein enrollment information comprises information selected from the group consisting of debit card account number and authentication scheme. 
     
     
         18 . The system according to  claim 16 , wherein the financial network comprises an EFT network. 
     
     
         19 . The system according to  claim 16 , wherein the merchant does not receive a passcode or a personal information number (PIN) for an account associated with the debit card. 
     
     
         20 . A system for authenticating an electronic transaction between a consumer and a merchant, wherein the system comprises a computer-readable medium comprising a plurality of instructions that when executed control a processor to:
 receive account information associated with a debit card account from the consumer over the Internet, wherein the consumer accesses the Internet using a consumer's computer, and the account information does not include a passcode or a personal identification number (PIN) for the debit card account;   confirm enrollment of the debit card account for digital signature authentication from a financial institution;   receive consumer specific authentication parameters from the financial institution, wherein the consumer specific authentication parameters comprises an authentication scheme comprising a hosted or a local digital signature service;   send transaction information over the Internet to the consumer's computer for a digital signature;   send the authentication scheme over the Internet to the consumer's computer;   receive a digital signature from the consumer's computer over the Internet, wherein the digital signature does not include a passcode or personal identification number (PIN) for the debit card account, and the digital signature comprises encrypted portions of the transaction information;   send the transaction information and the digital signature comprising encrypted portions of the transaction information to the financial institution;   receive payment authorization from the financial institution; and   send a receipt URL to the financial institution, the receipt URL later sent to the consumer by the financial institution.

Join the waitlist — get patent alerts

Track US2016321657A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.